MEDIUM 6.9 NVD
CVE-2026-73609
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspac
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4ph-9xwf-wcj4
- https://www.vulncheck.com/advisories/siyuan-before-information-disclosure-via-getbookmarkl
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-13 via NVD.
vulnfeed aggregates 10540 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.